logoalt Hacker News

McScrooge • today at 6:38 PM • 2 replies • view on HN

https://docker.github.io/docker-agent/configuration/sandbox/

If, like me, you couldn't find any security-related info on the linked page.


Replies

gregwebs • today at 8:30 PM

Docker Agent is a harness. There is a sandbox mode that can be used to run it in docker sandbox (a VM, not a container). If you don't use sandbox mode then I assume it is running in a container.

If you don't want to use their harness then you wouldn't use docker agent and instead use their `sbx` cli to run the harness of your choice (claude, codex, pi, etc).

I think it will be great if Docker can get people used to using secure VMs. I am developing a similar project (still a work in progress): https://github.com/gregwebs/agent-vm

➕ show 1 reply
ShinyLeftPad • today at 7:43 PM

i remember going through the entire docs of docker sandbox and there was not one mention of attack vectors. did they fix that?

➕ show 1 reply